nerdexam
RSA

050-SEPROGRC-01 · Question #56

In the Vendor Management solution, how is the vendor tier determined?

The correct answer is D. The answers to business impact, financial viability, and privacy analyses are combined to. In RSA Archer Vendor Management, the vendor tier is calculated automatically by combining the results of business impact, financial viability, and privacy analyses rather than being set manually.

Implementing GRC Use Cases (e.g., Policy, Risk, Vendor Management)

Question

In the Vendor Management solution, how is the vendor tier determined?

Options

  • AThe vendor relationship manager is able to manually type in the vendor tier.
  • BThe vendor tier is pulled from an external database maintained by a third party.
  • CA representative from each vendor company can enter a tier through an external site.
  • DThe answers to business impact, financial viability, and privacy analyses are combined to

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    4% (2)
  • C
    17% (9)
  • D
    72% (38)

Why each option

In RSA Archer Vendor Management, the vendor tier is calculated automatically by combining the results of business impact, financial viability, and privacy analyses rather than being set manually.

AThe vendor relationship manager is able to manually type in the vendor tier.

Manual entry of the vendor tier by a relationship manager is not supported - the tier is system-calculated to maintain objectivity and consistency.

BThe vendor tier is pulled from an external database maintained by a third party.

RSA Archer Vendor Management does not pull tier data from an external third-party database; the calculation is performed internally using questionnaire responses.

CA representative from each vendor company can enter a tier through an external site.

Vendors do not self-report or self-assign their tier through any external portal; doing so would undermine the integrity of the risk-based classification.

DThe answers to business impact, financial viability, and privacy analyses are combined toCorrect

The platform aggregates the scored outputs from the business impact analysis, financial viability analysis, and privacy analysis questionnaires and uses the combined result to derive the vendor tier automatically, ensuring an objective, criteria-based classification for each vendor.

Concept tested: RSA Archer Vendor Management tier calculation methodology

Source: https://community.rsa.com/t5/archer-documentation/tkb-p/archer-documentation

Topics

#Vendor Management#vendor tier#business impact analysis#risk scoring

Community Discussion

No community discussion yet for this question.

Full 050-SEPROGRC-01 Practice